Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3436 articles · 210641 vulns · 37/41 feeds (7d)
← Back to list
7.5
CVE-2026-34486EXPLOITEDPATCHED
apache · tomcat

Apache Tomcat: Fix for CVE-2026-29146 allowed bypass of EncryptInterceptor

Description

Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.

Affected Products

VendorProductVersions
apachetomcat11.0.20, 10.1.53, 9.0.116

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
apachetomcatcert_advisory90%
atlassianbitbucketcert_advisory90%
atlassianbamboocert_advisory90%
atlassianconfluencecert_advisory90%
atlassianjiracert_advisory90%

References

  • https://lists.apache.org/thread/9510k5p5zdvt9pkkgtyp85mvwxo2qrly(vendor-advisory)

Related News (11 articles)

Tier B
CERT-FR27d ago
Bulletin d'actualité CERTFR-2026-ACT-034 (10 août 2026)
→ No new info (linked only)
Tier D
Heise Security29d ago
Angreifer attackieren IBM Langflow und Apache-Tomcat-Server
→ No new info (linked only)
Tier D
BleepingComputer31d ago
CISA warns of hackers exploiting Langflow, N-central, Apache Tomcat flaws
→ No new info (linked only)
Tier D
Infosecurity Magazine36d ago
Chinese Hacker Uses DeepSeek AI to Orchestrate Vulnerability Exploits
→ No new info (linked only)
Tier B
CERT-FR80d ago
Multiples vulnérabilités dans les produits Atlassian (18 juin 2026)
→ No new info (linked only)
Tier B
BSI Advisories80d ago
[NEU] [hoch] Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira und Jira Service Management: Mehrere Schwachstellen
→ No new info (linked only)
Tier D
The Hacker News138d ago
⚡ Weekly Recap: Vercel Hack, Push Fraud, QEMU Abused, New Android RATs Emerge & More
→ No new info (linked only)
Tier B
BSI Advisories148d ago
[NEU] [mittel] Apache Tomcat und Tomcat Native: Mehrere Schwachstellen
→ No new info (linked only)
Tier B
CERT-FR149d ago
Multiples vulnérabilités dans Apache Tomcat (10 avril 2026)
→ No new info (linked only)
Tier C
oss-security149d ago
CVE-2026-34486: Apache Tomcat: Fix for CVE-2026-29146 allowed bypass of EncryptInterceptor
→ No new info (linked only)
Tier C
VulDB149d ago
CVE-2026-34486 | Apache Tomcat up to 9.0.116/10.1.53/11.0.20 missing encryption
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.17.5 NONE
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
org.apache.tomcat:tomcat@11.0.21org.apache.tomcat:tomcat@10.1.54org.apache.tomcat:tomcat@9.0.117org.apache.tomcat:tomcat-tribes@11.0.21org.apache.tomcat:tomcat-tribes@10.1.54org.apache.tomcat:tomcat-tribes@9.0.117
CWECWE-311
PublishedApr 9, 2026
Last enriched149d agov2
Trending Score2
Source articles11
Independent8
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

MEDIUMCVE-2026-49844EXP
Apache Log4j API: Improper serialization of non-finite floating-point values in MapMessage.asJson()
Trending: 45
CRITICALCVE-2026-59084EXP
Apache Tomcat: EncryptInterceptor requirements not clearly documented
Trending: 22
CRITICALCVE-2026-59083EXP
Apache Tomcat: Incorrect URL decoding in RewriteValve may allow security control bypass
Trending: 22
HIGHCVE-2026-66142
Apache Neethi: Uncontrolled recursion in policy processing
Trending: 20
CRITICALCVE-2026-65905
Apache Tomcat: Limited replay attack possible with DIGEST authentication
Trending: 20

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Apr 9, 2026
Discovered by ZDM
Apr 9, 2026
Updated: description, severity, cvssEstimate, activelyExploited
Apr 9, 2026
Actively Exploited
Aug 10, 2026
Exploit Available
Aug 10, 2026
Patch Available
Aug 10, 2026

Version History

v2
Last enriched 149d ago
v2Tier C149d ago

Updated description with new details, changed severity to HIGH, set CVSS estimate to 7.5, and marked the vulnerability as actively exploited.

descriptionseveritycvssEstimateactivelyExploited
via VulDB
v1149d ago

Initial creation